refactor: rename the encryption key to what it actually protects
CALENDAR_ENCRYPTION_KEY was named after the calendar module because that module needed encryption first, in Phase 5. Every feature since has shared the same key -- SMTP, the DKV and tender mailboxes, and as of today the LDAP bind password -- so the name has been describing one of five users rather than the thing itself, and each new feature inherited the confusion. TESSERA_ENCRYPTION_KEY is the name now. The old one is still read, because renaming outright would stop every existing installation at the next start: their .env carries the old name, and compose was just made to fail hard on a missing key. When only the old name is present the API logs a deprecation warning naming both, and when both are set the new one wins -- otherwise a half-migrated .env would encrypt with one key and decrypt with the other. CalendarCryptoService becomes CryptoService in its own global CryptoModule. Four modules used to import CalendarModule purely to reach the provider, which read as a dependency on calendars where there was none; that import is gone. Compose keeps the hard failure: without either name the stack refuses to start. Verified in both files for all three cases -- neither name set (abort), only the old name (starts), only the new name (starts). Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
@@ -1,5 +1,6 @@
|
||||
import { Injectable, Logger, OnApplicationBootstrap } from '@nestjs/common';
|
||||
import { CalendarCryptoService } from '../calendar/crypto.service';
|
||||
import { CryptoService } from '../crypto/crypto.service';
|
||||
|
||||
import { PrismaService } from '../prisma/prisma.service';
|
||||
import {
|
||||
CreateFieldMappingDto,
|
||||
@@ -8,7 +9,7 @@ import {
|
||||
} from './dto/ldap-config.dto';
|
||||
|
||||
/**
|
||||
* Shape of a stored AES-256-GCM value as CalendarCryptoService writes it:
|
||||
* Shape of a stored AES-256-GCM value as CryptoService writes it:
|
||||
* `iv:authTag:ciphertext`, all hex. Used to tell an encrypted value apart from
|
||||
* a legacy plaintext one that predates the encryption of this column.
|
||||
*/
|
||||
@@ -37,7 +38,7 @@ export class LdapConfigService implements OnApplicationBootstrap {
|
||||
|
||||
constructor(
|
||||
private prisma: PrismaService,
|
||||
private readonly crypto: CalendarCryptoService,
|
||||
private readonly crypto: CryptoService,
|
||||
) {}
|
||||
|
||||
/**
|
||||
@@ -100,7 +101,7 @@ export class LdapConfigService implements OnApplicationBootstrap {
|
||||
// A wrong or rotated key must not read as "no password configured" —
|
||||
// that would silently turn an authenticated bind into an anonymous one.
|
||||
this.logger.error(
|
||||
`LDAP-Bind-Passwort konnte nicht entschluesselt werden (falscher CALENDAR_ENCRYPTION_KEY?): ${(err as Error).message}`,
|
||||
`LDAP-Bind-Passwort konnte nicht entschluesselt werden (falscher TESSERA_ENCRYPTION_KEY?): ${(err as Error).message}`,
|
||||
);
|
||||
throw err;
|
||||
}
|
||||
|
||||
@@ -1,6 +1,5 @@
|
||||
import { Module } from '@nestjs/common';
|
||||
import { ScheduleModule } from '@nestjs/schedule';
|
||||
import { CalendarModule } from '../calendar/calendar.module';
|
||||
import { GroupsModule } from '../groups/groups.module';
|
||||
import { UserModule } from '../user/user.module';
|
||||
import { LdapConfigService } from './ldap-config.service';
|
||||
@@ -19,14 +18,11 @@ import { LdapService } from './ldap.service';
|
||||
* syncBoundGroupsForTenant() (Plan 16-03, D-06) — no cycle: GroupsModule
|
||||
* imports neither LdapModule nor UserModule.
|
||||
*
|
||||
* CalendarModule is imported for CalendarCryptoService, which encrypts the
|
||||
* bind password at rest — the same provider SettingsModule, DkvModule and
|
||||
* TendersModule already use for their own credentials. The name is a
|
||||
* historical accident (the calendar module happened to need encryption
|
||||
* first), not a statement about ownership.
|
||||
* The bind password is encrypted at rest via CryptoService from the global
|
||||
* CryptoModule — the same provider every other stored credential uses.
|
||||
*/
|
||||
@Module({
|
||||
imports: [ScheduleModule.forRoot(), UserModule, GroupsModule, CalendarModule],
|
||||
imports: [ScheduleModule.forRoot(), UserModule, GroupsModule],
|
||||
controllers: [LdapController],
|
||||
providers: [LdapService, LdapConfigService, LdapSyncScheduler],
|
||||
exports: [LdapService, LdapConfigService],
|
||||
|
||||
Reference in New Issue
Block a user